| Ãë¾àÁ¡ID |
28026 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
139,445 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
SMB |
| »ó¼¼¼³¸í |
ÇØ´ç Microsoft SQL ¼¹ö´Â ¼³Ä¡ ÆÐ½º¿öµå¸¦ ¾ÈÀüÇÏÁö ¾ÊÀº °÷¿¡ ÀúÀåÇϰí ÀÖ´Ù. MS SQL ¼¹öÀÇ ¼³Ä¡ °úÁ¤¿¡¼ setup.iss ¼³Ä¡ ÆÄÀÏÀ̳ª sqlstp.log ÆÄÀϰú sqlspX.log ·Î±× ÆÄÀϵ鿡 ¾ÏȣȵÇÁö ¾ÊÀº ä·Î, ȤÀº Çã¼úÇÑ ¾ÏÈ£È ¹æ½ÄÀ¸·Î ÀúÀåµÉ ¼ö ÀÖ´Â ¾î¶² ¼³Ä¡ ÆÐ½º¿öµåµéÀ» ³²°Ü ³õÀ» ¼ö ÀÖ´Ù. ÀÌ ÆÄÀϵéÀº µÎ ±ºµ¥¿¡ ±â·ÏµÈ´Ù. ù¹øÂ°´Â %WINNT% µð·ºÅ丮 (´ëºÎºÐÀÇ ½Ã½ºÅÛÀº C:\Winnt)¿¡ ÀÖ´Ù. µÎ¹øÂ° Àå¼Ò´Â %SQLSERVERINSTANCE%\install ÀÌ´Ù. ÀÌ ÆÄÀϵéÀº ºÎÀûÀýÇÑ ÆÄÀÏ ¾×¼¼½º ±ÇÇÑÀ» °¡Áö°í »ý¼ºµÇ±â ¶§¹®¿¡ SQL ¼¹ö°¡ ÀÛµ¿Çϰí ÀÖ´Â ½Ã½ºÅÛ»ó¿¡ ·Î±×¿Â ÇÒ ¼ö ÀÖ´Â ¿ø°ÝÁöÀÇ °ø°ÝÀÚ¶ó¸é ±× ÆÄÀϵéÀ» ¾×¼¼½ºÇÏ¿© ÆÐ½º¿öµåµéÀ» ã¾Æ³¾ ¼ö ÀÖ´Ù. À̰ÍÀº °ø°ÝÀÚ°¡ SQL ¼¹ö¿¡ ´ëÇÑ °ü¸®ÀÚ ±ÇÇÑÀ» ¾òÀ» ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ¿¹¸¦µé¾î, setup.iss ÆÄÀÏÀ» ¿ÀÇÂÇÏ¸é ´ÙÀ½°ú °°Àº ÅØ½ºÆ®µéÀ» º¼ ¼ö ÀÖÀ» °ÍÀÌ´Ù:
[ServerConnect-0] NTAuthentication=0 SQLAuthentication=1 svPassword=0536f618eca8
"svPassword="À¸·Î ½ÃÀÛÇÏ´Â ¶óÀÎÀº °£´ÜÇÏ°Ô ÇØµ¶ÇÒ ¼ö ÀÖ´Â ¾ÏÈ£¸¦ °¡Áö°í ÀÖ´Ù.
* Âü°í: http://www.cert.org/advisories/CA-2002-22.html http://www.kb.cert.org/vuls/id/338195 http://archives.neohapsis.com/archives/bugtraq/2002-07/0108.html http://marc.theaimsgroup.com/?l=bugtraq&m=102640092826731&w=2 http://marc.theaimsgroup.com/?l=vuln-dev&m=102640394131103&w=2 http://www.appsecinc.com/resources/alerts/mssql/02-0009.html
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/bid/5203
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Microsoft MSDE 1.0 Microsoft SQL Server 2000 Microsoft SQL Server 7.0 Microsoft Windows Any version |
| ÇØ°áÃ¥ |
1. ÀÌ Ãë¾àÁ¡¿¡ ÀÇÇØ ÆÐ½º¿öµåµéÀÌ ³ëÃâµÇ¾úÀ» ¼ö ÀÖÀ¸¹Ç·Î ÆÐ½º¿öµå¸¦ ¹Ù²ã¾ß ÇÑ´Ù. sa °èÁ¤¿¡ ´ëÇÑ ÆÐ½º¿öµå´Â SQL Query â¿¡¼ ´ÙÀ½°ú °°Àº ¸í·ÉÀ» ÀÌ¿ëÇÏ¿© ¹Ù²Ü ¼ö ÀÖ´Ù.
exec sp_password NULL,'hard!2guess','sa'
2. ÆÐ½º¿öµåµéÀ» °¡Áö°í ÀÖ´Â ¸ðµç ÆÄÀϵéÀ» ã¾Æ¼ »èÁ¦ÇÏ¿©¾ß ÇÑ´Ù. ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®»ç´Â ¾×¼¼½º °¡´ÉÇÑ ¸ðµç µð·ºÅ丮·ÎºÎÅÍ ÆÐ½º¿öµåµéÀ» Á¦°ÅÇØ ÁÖ´Â killpwd.exe ¶ó´Â À¯Æ¿¸®Æ¼¸¦ Á¦°øÇϰí ÀÖ´Ù. ÀÌ ÆÄÀÏÀº ¾Æ·¡¿¡ ÀÖ´Â ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½Ã¹° MS02-035 ·ÎºÎÅÍ ´Ù¿î·Îµå °¡´ÉÇÏ¸ç ¼¹ö»ó¿¡¼ ¼öÇà½ÃŰ¸é µÈ´Ù: http://www.microsoft.com/technet/security/bulletin/MS02-035.asp |
| °ü·Ã URL |
CVE-2002-0643 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|